The Biggest Thefts and Hacks in Gaming History: The $620 Million Axie Infinity Hack, Stolen CS2 Skins, and the GTA 6 Leak
The largest theft connected to video games did not happen in a virtual world but on Ronin, the blockchain network that powered Axie Infinity. In March 2022, attackers drained approximately $620 million in cryptocurrency from it. According to the FBI, North Korean hackers were behind the attack. Stories like this are not limited to crypto games, however. This article covers CS inventories worth millions of dollars, elaborate scams in EVE Online, and the Rockstar hack that leaked around 90 videos from an early version of GTA 6.
Key Takeaways
- The largest theft in gaming was the March 2022 hack of the Ronin network used by Axie Infinity: attackers stole 173600 ETH and 25.5 million USDC worth approximately $620 million. The FBI attributed the attack to North Korea's Lazarus Group;
- Most of the money was laundered through the Tornado Cash crypto mixer, which was subsequently placed on the US sanctions list. The sanctions were lifted in 2025. Only a small portion of the stolen funds was recovered, but Axie Infinity players were later fully reimbursed using money from a separate $150 million investment round;
- Ronin is not the only crypto gaming platform to have been robbed: attackers stole tokens worth approximately $290 million from PlayDapp in 2024 and around $140 million from Vulcan Forged in 2021;
- CS:GO and CS2 inventories worth millions are also targeted. In 2022, collector HFB lost more than $2 million in skins, although Valve restored everything, even recreating a rare Dragon Lore. In 2025, extortionists destroyed a collection of rare Katowice 2014 stickers worth around $300,000 in a single night;
- In EVE Online, players spend years carrying out scams, “contract killings,” and Ponzi schemes involving tens of thousands of real dollars — while courts in the Netherlands have already treated virtual theft as a real crime;
- Criminals also target game studios: hackers stole and leaked around 90 videos from an early build of GTA 6, while CD Projekt Red, Insomniac, EA, and Capcom have faced ransom demands or had source code and plans for future games stolen;
- How can players protect themselves? Enable two-factor authentication through Steam Guard, use unique passwords, and never click suspicious “prize” links. Many account thefts begin with phishing rather than some brilliant technical exploit.
How $600 Million Was Stolen From a Game About Cute Creatures
Axie Infinity is a game about cute creatures called Axies, which players breed, upgrade, and pit against one another in battles while earning real money. At its peak in 2021, millions of people played it, and for some users in the Philippines and other countries, it became a full-time source of income. To keep this entire economy running quickly and cheaply, developer Sky Mavis built a separate blockchain network for the game called Ronin. That network proved to be the weak link.
On March 23, 2022, attackers gained control of a majority of the nodes used to approve transactions within the network — 5 out of 9 — and emptied the shared bridge in 2 transactions. The bridge served as the repository through which money entered and left the game. The attackers stole 173600 ETH and 25.5 million USDC. The loss was not discovered immediately. Everything appeared normal for 6 full days, until March 29, when an ordinary player failed to withdraw 5,000 ETH and raised the alarm.
There was an almost absurd detail: while the theft went unnoticed for 6 days, the value of Ether increased, causing the stolen haul to grow from $540 million to $620 million on its own. The thieves became richer without doing anything. At the time, it was the largest cryptocurrency hack in history, surpassing the previous record set by the $611 million Poly Network attack. The Poly Network hacker, however, eventually returned almost all the stolen funds. In the Ronin case, no one suffered a similar attack of conscience. Investigators later managed to trace and recover only a small portion of the stolen amount.
On April 14, 2022, the FBI officially identified those responsible: the attack was carried out by Lazarus Group and APT38, hacking organizations linked to the North Korean government. According to the bureau, these groups were “responsible for the theft of $620 million in cryptocurrency.” The same hackers are suspected of attacking banks and cryptocurrency exchanges around the world, while the proceeds reportedly help fund North Korea's military programs, according to US and UN assessments.
For context, the February 2025 hack of the Bybit cryptocurrency exchange, which resulted in the theft of $1.5 billion, stripped Ronin of its title as the largest cryptocurrency heist overall. Bybit is an exchange rather than a game, however, so Ronin still holds the absolute record among gaming-related cases. The perpetrators have never been caught, either: Lazarus operates under the protection of an entire state, so extradition is not going to happen. The more interesting question is how anyone can steal half a billion dollars without having the money traced by governments around the world.
Where Do You Put $600 Million That No Bank Will Accept?
The weak point in major play-to-earn thefts is not usually the game itself but the money attached to it. Attackers generally target one of 3 areas: a bridge between blockchains, which stores funds as they move into and out of the game; private wallet keys; or a vulnerability in a smart contract. In Ronin's case, it was the bridge that failed. The attack did not begin with sophisticated code but with a person: according to investigators, everything started with a fake job offer sent to one of Sky Mavis' engineers. It was classic social engineering, not magic.
The main question is what to do with hundreds of millions of dollars in cryptocurrency that no bank will accept. The answer is crypto mixers — services that blend funds together to break the transaction trail. More than $455 million from the Ronin haul passed through one such service, Tornado Cash. The response was unprecedented: on August 8, 2022, the US government imposed sanctions on Tornado Cash itself. What made the decision unusual was that the sanctions targeted neither a person nor a company, but what was essentially autonomous code. The US Treasury explicitly cited the service's use by North Korea's Lazarus Group, including to launder funds stolen from Axie Infinity.
Those sanctions ultimately did not last. In November 2024, an appeals court sided with the critics, ruling that immutable smart contracts could not be sanctioned as someone's property. In March 2025, after reviewing the case, the Treasury removed Tornado Cash from the sanctions list entirely.
Only a small amount was recovered. On September 8, 2022, investigators working with analysts from Chainalysis seized approximately $30 million — around one-tenth of the stolen funds and the first recorded instance of money being recovered from hackers linked to North Korea. Later, in 2024, Norwegian authorities helped recover another $5.7 million. The rest disappeared.
One figure makes it clear that the Ronin hack was not an isolated emergency: cryptocurrency hacks resulted in the theft of $3.8 billion in 2022 alone, according to Chainalysis data, and organizations linked to North Korea stole almost half of it. Over the years, North Korean hackers have reportedly taken around $6.75 billion in total. That is comparable to the annual military budget of a small country, and UN reports suggest that this is where some of the money goes — toward the country's missile program. In other words, cute Axies ended up helping fund a real military program.
The Ronin hack was not a one-off incident but the most notorious episode in an entire criminal industry, and gaming platforms are regularly caught in its path. In December 2021, attackers stole private wallet keys from the crypto game Vulcan Forged and withdrew approximately $140 million. In February 2024, the PlayDapp platform was drained after an attacker found a vulnerability in its smart contract and simply minted tokens worth almost $290 million, according to an estimate from Elliptic analysts. It remains the second-largest gaming-related theft in history, behind only Ronin, and further proof that the vulnerable part is not the entertainment itself but the money attached to it.
Axie Infinity itself managed to recover. Just one week after the attack, Sky Mavis secured a $150 million investment round led by the Binance exchange specifically to reimburse players. Victims received everything they had lost, and the bridge reopened in late June 2022 after 3 audits. Axie Infinity was fortunate to have an active company and investors behind it. Most victims of the other thefts on this list had no such safety net.
An Inventory Worth More Than an Apartment: Million-Dollar Knives and Revenge With Negev Machine Guns
A blockchain network is not required to store a fortune. An ordinary CS2 or Dota 2 inventory can be worth more than an apartment: rare skins, knives, and gloves have been traded for real money for years, while the most prestigious items cost as much as a good car. All of this is stored in an account protected only as well as its owner has bothered to secure it.
A revealing incident occurred in June 2022 and involved the legendary collector known as HFB. His account was hijacked with more than $2 million in skins inside: 7 Souvenir AWP Dragon Lores and an extremely rare Karambit with a Blue Gem pattern, which alone was valued at around €1.2 million. The thieves managed to resell some of the items, but Steam reversed the trades, and everything was returned to its owner. Valve went even further: the only Dragon Lore that could not be recovered was simply recreated. For the first time since 2016, the company made an exact copy and gave it to the collector.
Another case involved an attacker who not only stole an account but also attempted to destroy the collection stored on it. In November 2025, the account of a collector known as Hawkeye was hacked. It contained a complete set of Katowice 2014 Holo stickers, some of the most expensive stickers in the game. A single Titan Holo is worth more than $70,000, while the complete set was valued at around $300,000. The hacker demanded a ransom in Bitcoin. When it was not paid, the attacker applied the entire collection to cheap Negev machine guns and then scraped the stickers off. In CS, this action is irreversible: used stickers disappear from the inventory and cannot be restored. Only Valve could save the collection. Its support team reversed every action overnight and returned the stickers. The company later admitted that the hack itself had been made possible by its own mistake: a support agent violated procedure and restored access to the wrong person.
Entire marketplaces are targeted as well as private collectors. In August 2022, CS.Money, one of the largest skin-trading platforms, was hacked. The attackers gained access to its trading bots and transferred items worth approximately $6 million through around 100 accounts. The stolen goods were distributed to bloggers and traders in an attempt to obscure the trail, while the service itself had to go offline.
Large-scale thefts of in-game items often begin with phishing. Between 2018 and 2021, trade interception was a common scheme: users were lured to a fake trading website, which gave attackers access to their accounts. The scammers then quietly replaced the recipient during an exchange. Because the list of items remained unchanged, the victim confirmed the transaction without noticing the substitution. The skins were usually impossible to recover because Steam did not reverse completed trades. In July 2025, Valve introduced Trade Protection, which allows users to reverse a suspicious exchange within 7 days.
Phishing has not disappeared; it has simply become more sophisticated. In March 2025, a campaign promoting a fake “free CS2 case” in the name of esports team NAVI spread online. Victims were drawn in through YouTube and shown a fake Steam login window virtually indistinguishable from the real one. In February of the same year, scammers hijacked YouTube channels and streamed recorded gameplay as fake “live broadcasts” featuring stars such as s1mple and NiKo during IEM Katowice. Viewers were redirected to fraudulent login pages and “double your crypto” schemes. Some victims lost $100,000 or more.
Adult collectors are not the only targets. “Beaming” has become an organized practice in Roblox: attackers hijack accounts, often belonging to children, to steal limited items with unique serial numbers and resell them for real money outside the game. Some victims have lost items worth half a million dollars, while one group stole more than 600,000 accounts around the turn of 2025–2026.

EVE Online: Scams Causing Thousands of Dollars in Losses
In EVE Online, espionage, betrayal, and the theft of corporate assets do not violate the rules. Major in-game scams have therefore long been part of the project's history. Their losses are often converted into real money, although such estimates remain theoretical because ISK cannot officially be withdrawn from the game. The cash equivalent is calculated using the cost of game time that can be purchased with in-game currency.
One of the best-known scams took place in 2005. The Guiding Hand Social Club carried out an operation that Guinness World Records recognized as the most hostile corporate takeover in EVE Online history. An agent spent around 10 months earning the trust of Mirial, the leader of a major corporation, and eventually gained access to her assets. During a coordinated attack, Guiding Hand Social Club members destroyed Mirial's ship and stole property worth approximately 30 billion ISK. Based on the price of game time at the time, the haul was valued at around $16500.
One year later, in 2006, another theft occurred that still holds the Guinness World Record for the “largest virtual heist in an MMO.” A player known as Cally founded the in-game EVE Intergalactic Bank, collected deposits from across the server, then staged his own death and disappeared with the money. He took approximately 790 billion ISK, worth around $29,000. Once again, there were no consequences because he had technically broken no rules.
In 2010, a scammer known as Bad Bobby used a clever share-manipulation scheme within Titans4U to force through the vote he needed, gain access to blueprints for enormous Titan ships, and steal assets worth approximately $45,000. In 2011, a genuine Ponzi scheme called Phaser Inc collapsed. It had promised returns of 5% per week, collected money from more than 4,000 players, and left its organizers with over 1 trillion ISK, worth around $50,000. At the time, it was the largest documented scam in the game.
Ricdic, the head of the in-game bank EBANK, did receive a ban, but not for taking depositors' money. In 2009, he withdrew approximately 200 billion ISK from the bank and sold the currency for around $5,000. He said he needed the money for a down payment on a house and his son's medical treatment. CCP banned the account for selling in-game currency for real money: theft is permitted in EVE Online, but real-money trading is not.
Not every major loss in EVE Online is caused by theft. In January 2014, the Bloodbath of B-R5RB took place, a battle lasting around 21 hours in which 75 Titans and numerous other ships were destroyed. Total losses were estimated at approximately $300,000, although this figure was only a theoretical cash equivalent of the destroyed property. The battle began after one coalition failed to pay the fee required to maintain control of the B-R5RB system, leaving it vulnerable to capture.
Large-scale scams continued in later years. In 2023, a player known as Jay Amazingness exploited his access to Goonswarm assets and stole property worth more than 4 trillion ISK.
The theft of virtual property can sometimes lead to criminal charges. In 2007, Dutch authorities arrested a 17-year-old who had gained access to other users' Habbo Hotel accounts and stolen virtual furniture worth several thousand euros. In another case, 2 teenagers assaulted a peer and threatened him with a knife, forcing him to hand over an amulet and mask from RuneScape. In 2012, the Supreme Court of the Netherlands confirmed that virtual items could legally be considered stolen property. One of those convicted received 144 hours of community service.

Studio Hacks: The GTA 6 Leak and Ransom Demands for Source Code
A separate category involves attacks on game studios rather than players. The best-known example occurred on September 18, 2022, when a user known as teapotuberhacker posted around 90 videos from an early version of GTA 6 on GTAForums, along with fragments of internal data. Years before release, the public saw the game's 2 protagonists, Vice City, and unfinished gameplay scenes for the first time. Rockstar confirmed the material was genuine the following day, describing the incident as a “network intrusion.” Take-Two reassured investors that the attack had not affected development schedules or online services. The studio later estimated its direct losses in court at approximately $5 million, along with thousands of staff hours spent investigating the incident.
The hacker was Arion Kurtaj, a 17-year-old member of the international hacking group Lapsus$, who was also linked to the Uber breach. He gained access to Rockstar's systems through the company's internal Slack messenger. At the time of the attack, Kurtaj was out on bail under police supervision, and his laptop had been confiscated. Despite this, he hacked the company from a Travelodge hotel room using a smartphone, the hotel television, and an Amazon Fire TV Stick.
Because of his severe autism, Kurtaj was deemed unfit to participate in a conventional trial. In August 2023, the jury was therefore not asked to determine his criminal responsibility, but only whether he had committed the acts attributed to him. It concluded that he had. In December, Kurtaj was placed indefinitely in a secure psychiatric hospital, where he was to remain until doctors considered him safe for society.
By July 2026, Kurtaj had been transferred from the hospital to a regular prison. He is due to face a full criminal trial in November — the same month GTA 6 is scheduled for release.
The Rockstar hack resulted in the publication of GTA 6 materials, but in many other cases, stolen data is used for extortion. In February 2021, the HelloKitty group encrypted CD Projekt Red's servers and stole the source code for Cyberpunk 2077, The Witcher 3, and Gwent. The studio publicly refused to pay the ransom. The attackers then put the data up for auction with an opening bid of $1 million and offered the complete archive for an immediate purchase of $7 million. The extortionists later claimed that they had found a buyer.
A similar attack occurred in December 2023. The Rhysida group demanded that Insomniac Games pay a ransom of $2 million in Bitcoin. The studio and Sony refused, after which the attackers published around 1.3 million files totaling almost 1.7TB. The archive contained materials from Marvel's Spider-Man 2 and Marvel's Wolverine, internal correspondence, HR documents, and scans of employees' passports. The stolen files also included an agreement between Sony and Marvel outlining plans for game releases through 2035.
Major data breaches had occurred before then. In 2011, the PlayStation Network hack exposed information from 77 million accounts and left the service unavailable for 23 days. Sony estimated the related expenses at approximately $170 million. In late 2020, Capcom refused to pay the $11 million demanded by the Ragnar Locker group, after which the attackers published corporate documents and personal information. According to the company's estimate, the breach may have affected almost 400,000 people.
In summer 2021, hackers stole approximately 780GB of data from Electronic Arts, including the source code for FIFA 21 and the Frostbite engine. According to available information, they purchased access to the company's Slack on the black market for approximately $10, then impersonated an employee who had lost their phone and persuaded technical support to grant them access to the system. The stolen archive was offered for sale for $28 million, although no reports of a buyer ever appeared.
Riot Games also refused to pay a $10 million ransom demand in 2023. The 2024 attack on Kadokawa may have ended differently: according to unconfirmed reports, the Japanese company paid approximately $3 million. The attackers published some of the stolen files anyway. Paying a ransom does not guarantee that the data will be deleted or remain private.

How to Avoid Getting Hacked: What Actually Works
All of this sounds alarming, but there is some good news. Cryptocurrency exploits such as the Ronin and PlayDapp attacks involve vulnerabilities in code and wallets, so individual players have little control over them. The theft of conventional gaming accounts, however — which accounts for a significant share of personal losses — usually comes down to human error: a fake email, a fraudulent link, stolen cookies from an active session, or a login window indistinguishable from the real one. Protection therefore begins with good habits. These measures genuinely reduce the risk.
Two-factor authentication. Use Steam Guard, an authenticator app, and confirmation codes for every login and trade. This single measure prevents most account thefts: even if someone obtains your password, they cannot gain access without the second factor. There is an important caveat: two-factor authentication will not protect against the theft of an active session through stolen cookies or a mistake by customer support. Hawkeye had Steam Guard enabled, but a Valve employee still gave someone else access to his account. Even so, this remains the most important security measure. If you do only one thing on this list, make it this one.
A unique password for every service, plus a password manager. A huge proportion of account thefts do not involve hacking at all but credential stuffing: a username and password leaked from some forgotten forum also grant access to your Steam account because you reused the same password everywhere.
Check the website address before entering your username and password. A pop-up window does not automatically indicate fraud: the official “Sign in through Steam” button opens a similar window. Pay attention to the address bar. Browser authentication takes place on steamcommunity.com, while official Steam websites use the steampowered.com, steamcommunity.com, and help.steampowered.com domains. Any other address, even one designed to resemble an official domain, should raise suspicion. It is safer to open the website yourself instead of following links from chats or video descriptions.
A “free skin,” “vote for my team,” “double your crypto,” or an unexpected gift from a friend — all of these are common scams. Your friend's account may have been stolen an hour ago. An attractive offer that requires you to log in or confirm something urgently is almost always a trap.
Do not give trading keys or tokens to third-party websites. No legitimate service will ask for your Steam API key to complete a “quick trade.”
Cryptocurrency requires separate security precautions. Use a hardware wallet for large amounts, never keep everything in a single hot wallet, and remain skeptical of play-to-earn projects promising guaranteed returns. The difference from conventional gaming accounts is fundamental: Steam will at least occasionally reverse thefts — Hawkeye and HFB were fortunate — while blockchain transactions are irreversible, and there is no support team to call.
Perfect protection does not exist, but the difference between “stolen in a minute” and “the attackers failed” usually comes down to two-factor authentication and basic caution. No individual user can stop North Korean hackers or fix vulnerabilities in smart contracts, but many account thefts still begin with a single careless click. This part depends entirely on you: enable two-factor authentication now, while you are reading this sentence.

Which gaming-related crime left the strongest impression on you, and which cases did we miss? Share your thoughts in the comments.
Which Theft or Hack Impressed You the Most?
FAQ
What Is the Largest Hack in Gaming History?
In March 2022, attackers stole 173600 ETH and 25.5 million USDC from Ronin, the blockchain network created for Axie Infinity. The assets were worth approximately $620 million when the breach was discovered. The FBI attributed the attack to North Korea's Lazarus Group. The 2025 attack on the Bybit exchange later became the largest theft in the wider cryptocurrency industry, but Ronin still holds the record among gaming-related projects.
Was the Money Stolen From Axie Infinity Recovered?
Law enforcement recovered only part of the stolen funds: approximately $30 million in 2022 and another $5.7 million later with assistance from Norwegian authorities. Sky Mavis also raised $150 million from investors and used its own funds to restore the backing of user assets. However, funds from the Axie DAO treasury were treated separately, so it would be inaccurate to claim that the entire stolen amount was recovered.
Have Other Gaming Projects Been Hacked?
Yes. In 2024, attackers drained assets worth approximately $290 million from the crypto gaming platform PlayDapp, while Vulcan Forged lost around $140 million in 2021. Traditional gaming companies also regularly have source code, personal data, and internal documents stolen. CD Projekt Red, Insomniac Games, Riot Games, Electronic Arts, and Capcom have all experienced such attacks.
Can Someone Be Punished for Stealing Virtual Items?
Yes. In 2012, the Supreme Court of the Netherlands ruled that virtual RuneScape items could be treated as stolen property. As early as 2007, Dutch authorities arrested a teenager who had stolen virtual furniture from Habbo Hotel accounts. Under certain circumstances, the theft of in-game valuables can result in real criminal liability.
Who Hacked Rockstar and Published the GTA 6 Materials?
The attacker was Arion Kurtaj, a 17-year-old member of the Lapsus$ group. In September 2022, he published around 90 videos from an early version of GTA 6. Because of Kurtaj's condition, the jury initially determined only whether he had committed the alleged acts rather than whether he was criminally responsible. He was placed in a secure psychiatric hospital and later transferred to prison. A new trial is scheduled for November 2026.
Can CS Skins and Stickers Really Be Worth Millions of Dollars?
Yes. Rare knives, skins, and stickers can be worth hundreds of thousands or even millions of dollars. Accounts containing valuable inventories therefore regularly become targets for attackers. The best-known cases include the theft of approximately $2 million in items from trader HFB and the hack of collector Hawkeye's account, whose stickers were valued at $300,000.
How Can I Protect My Gaming Account From Theft?
Use a unique password, a password manager, and two-factor authentication such as Steam Guard. Do not follow links promising free items or asking you to vote for a team. Check the website address before signing in, and never give anyone your password, confirmation codes, or other login information. Most accounts are stolen through phishing and social engineering rather than a direct attack on the service.
Are Theft and Scams Allowed in EVE Online?
Some forms of deception, betrayal, and appropriation of in-game assets are not prohibited by EVE Online's rules and are considered part of the gameplay. Selling ISK for real money, however, violates the user agreement. This was why Ricdic, the head of EBANK who appropriated depositors' funds, was banned.
Do You Use Two-Factor Authentication on Your Gaming Accounts?
-
"See this gamertag — leave immediately": the Call of Duty: Black Ops 2 PlayStation port emptied out in a week because of one returning hacker -
New Exploit Lets Hackers Jailbreak a PS4 in About 20 Seconds -
Players are being told to delete MECCHA CHAMELEON immediately — except that advice is coming from the hacker, not the developers -
Hacker Linked to GTA 6 Leak Leaves Secure Hospital, Awaits Trial in Prison -
Zoom Issues Emergency Update: Hackers Could Take Over Your Computer Mid-Call


